by Leo Feyer
Server-side request forgery (SSRF) via unvalidated RSS feed URLs
Date: 2026-07-13
CVE ID: CVE-2026-57232
Description
A backend user with access to the Feed Reader module can cause the server to fetch arbitrary internal URLs.
Affected versions
Contao 5.3.35 up to 5.3.47
Contao 5.4
Contao 5.5
Contao 5.6
Contao 5.7 up to 5.7.8
Suggested solution
Upgrade to Contao 5.3.48 or 5.7.9.
Workaround
Disable the Feed Reader module.
More information
https://github.com/contao/contao/security/advisories/GHSA-87mg-5grr-rhwh